OwaAuth is a malicious web shell and credential-stealing implant used on Microsoft Exchange servers. It is installed as an ISAPI filter DLL and is loaded by the IIS worker process, allowing it to intercept web traffic and execute attacker-supplied commands through HTTP requests. The malware is known to masquerade as a legitimate Exchange component by using the name of a genuine Outlook Web App authentication library while placing the malicious DLL in a different Exchange directory, aiding defense evasion and blending into the server environment.
OwaAuth is associated with the China-linked espionage group commonly tracked as APT27, BRONZE UNION, and Threat Group-3390. It has been used to maintain access to compromised Exchange infrastructure, steal credentials, and support broader post-compromise activity. Its credential theft behavior includes capturing usernames and passwords, encrypting the collected data, and writing it to a local log for later retrieval. OwaAuth also supports command handling via specially crafted inbound HTTP requests and includes anti-forensics functionality such as timestomping files or directories.
The malware has been observed on enterprise email infrastructure and is best characterized as a server-side web shell tailored for Microsoft Exchange environments. Its use fits long-term espionage operations focused on persistence, credential access, and covert control of internet-facing servers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The threat actor also attempted to use OWA account credentials likely acquired during an earlier phase of the intrusion.
CTU researchers identified evidence of the group exploiting vulnerabilities in Internet-facing service desk software to gain an initial foothold... In multiple instances, CTU researchers observed artifacts from unsuccessful attempts to create a web shell on web-accessible JBOSS-based service desk software, followed by use of a functional shell to gain access to the environment.
The threat actor also attempted to use OWA account credentials likely acquired during an earlier phase of the intrusion.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
Akira has used legitimate names and locations for files to evade defenses.
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom web shell and credential stealer used on Microsoft Exchange OWA to capture submitted credentials.
Malware with a command to timestomp files or directories.
Software changes: ... OwaAuth
Malware that impersonates a legitimate Exchange OWA DLL by reusing its filename in a different path.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.